Deepseek Harness Portal
vocsong/deepseek-harness-portal · model-adapters
A multi-tenant platform that provisions and routes isolated DeepSeek Harness (dsh) instances — one container per user.
★ 2GitHub stars
2Forks
2026-09-04Last updated
JavaScriptLanguage
—License
Key features
- Registrationemail + one-time code (OTP), with optional username + password set during signup (so a new user can log in with credentials right away).
- Container dsh- , CPU/memory/swap/PID limits, read-only root + bounded tmpfs/logs, no capabilities, no-new-privileges, explicit isolated pasta networking, --restart unless-stopped
- image/dsh-security.patch applies reviewed transitive dependency floors and a matching frozen lockfile (production audit: zero known advisories at review time).
- Adminlog in as admin → Settings tab → email-domain whitelist, invite code, auth toggles.
- An invite code is enforced when the admin has set one.
Requirements
- Podman with a running machinepodman machine start
- A Cloudflare zone on your account, with the tunnel already authenticated
Install command
dsh plugin --profile web add github:vocsong/deepseek-harness-portal